Nutex Health confirms data theft in August cyberattack (The Gentlemen)
U.S. hospital and healthcare-facilities operator Nutex Health confirmed in an SEC filing that patient, employee, provider and financial information was accessed and exfiltrated in an August cyberattack claimed by the ransomware-as-a-service group The Gentlemen.
- Victim
- Nutex Health Inc.
On 31 August 2026, Nutex Health Inc. โ a Houston-based operator of hospitals and healthcare facilities across the United States โ filed an Item 1.05 Form 8-K with the U.S. Securities and Exchange Commission confirming that a material cybersecurity incident had occurred and that information stored on its servers had been accessed and exfiltrated by an unauthorized third party. The company had first disclosed unauthorized network activity a week earlier, in an Item 8.01 filing on 24 August.
Nutex said the compromised data included patient and employee information, credentialed-provider records, and business and financial information that is private and/or confidential. The ransomware-as-a-service group known as The Gentlemen added Nutex Health to its leak site and claimed responsibility โ the hallmark of a double-extortion attack, in which criminals both steal data and threaten to publish it.
What happened
Upon learning of the intrusion, Nutex activated its cybersecurity response plan, engaged an independent third-party response team and forensic experts, implemented containment measures, and notified law enforcement. A class-action complaint was filed against the company on 27 August in the U.S. District Court for the Southern District of Texas on behalf of individuals whose personal and protected health information may have been affected. As the data was published on the attackers' site, Nutex began the weeks-long process of downloading and analyzing it to determine its contents, scope and authenticity.
Why it matters
Healthcare operators remain among the most heavily targeted victims of ransomware, and the Nutex case shows the compounding consequences: a material SEC disclosure, exposure of sensitive patient and provider data, and near-immediate class-action litigation. It also reflects the double-extortion model's staying power, where publication of stolen data continues to pressure victims well after initial containment.
Timeline
Nutex Health discloses unauthorized activity on its network in an Item 8.01 Form 8-K filing with the SEC.
A class-action complaint is filed against the company in the Southern District of Texas.
Nutex files an Item 1.05 Form 8-K confirming a material cybersecurity incident with data accessed and exfiltrated.
Sources
- sec.govhttps://www.sec.gov/Archives/edgar/data/0001479681/000162828026058606/nutx-20260824.htm
- therecord.mediahttps://therecord.media/nutex-health-data-breach
- hipaajournal.comhttps://www.hipaajournal.com/nutex-health-data-breach/